Skip to content

Security & compliance

Card data protected to the highest standard.

NIXION TECH LIMITED is a PCI DSS Level 1 certified Service Provider. Security is not a feature we add on. It is how the whole platform is designed, operated and independently assessed every year.

PCI DSS

Level 1 Service Provider

Entity
NIXION TECH LIMITED
Validation
Level 1 Service Provider
Assessed by
Independent Qualified Security Assessor (QSA)
Frequency
Annual Report on Compliance

What Level 1 means

The most rigorous validation in the card industry.

The Payment Card Industry Data Security Standard (PCI DSS) is set by the PCI Security Standards Council, founded by the major card schemes. Level 1 is the highest validation level for service providers and requires independent assessment rather than self-assessment.

  • Annual on-site assessment

    An independent Qualified Security Assessor audits our people, processes and systems every year and issues a Report on Compliance.

  • Attestation of Compliance

    The assessment results in a signed Attestation of Compliance, which we share with merchants, partners and acquirers on request.

  • Quarterly external scans

    An Approved Scanning Vendor scans our internet-facing systems every quarter, alongside our own internal vulnerability scanning.

  • Penetration testing

    Internal and external penetration tests are carried out at least annually and after significant changes to our environment.

How we protect data

Layered controls across the platform.

Every layer, from the network to the people who operate it, is designed to keep cardholder data safe and to prove it to our assessors.

Tokenisation
Card numbers are replaced with tokens as soon as they reach us. Merchants store and reuse the token, never the card number.
Encryption in transit and at rest
All traffic is protected with TLS 1.2 or higher, and stored cardholder data is encrypted with strong cryptography and managed keys.
Network segmentation
The cardholder data environment is isolated from all other systems, with strictly controlled and monitored connections.
Strict access control
Least-privilege access, multi-factor authentication for all administrative access, and every action logged and attributable.
Continuous monitoring
Centralised logging, file integrity monitoring and alerting help us detect and respond to suspicious activity quickly.
Secure development
Code review, automated security testing, dependency scanning and formal change control on every release.

EMV 3-D Secure 2

Strong authentication, with less friction.

3-D Secure 2 shares rich transaction data with the card issuer, so most genuine customers are approved without a challenge, while higher-risk payments are verified in their banking app. It supports Strong Customer Authentication under PSD2 and can shift fraud liability to the issuer.

Supported programmes

  • Visa Secure
  • Mastercard Identity Check
  • American Express SafeKey
  • Discover and Diners Club ProtectBuy
  • JCB J/Secure
  • UnionPay 3-D Secure

Your PCI DSS scope

Choose how much card data you handle.

Every merchant that accepts cards must comply with PCI DSS. The integration you choose decides how much of that work falls on you.

  • Smallest scope

    Hosted payment page

    Customers enter their card details on our PCI DSS Level 1 certified page. Card data never touches your systems, and most merchants can validate with SAQ A, the shortest self-assessment questionnaire.

  • Smallest scope

    Payment links

    Customers pay on a secure page hosted by us, so no card data is handled by your website or staff.

  • Full control

    Server-to-server API

    Card data passes through your servers before reaching us. You keep full control of the checkout, and validate your own PCI DSS compliance, usually with SAQ D.

Your acquirer or Qualified Security Assessor confirms which self-assessment questionnaire applies to your business. We are happy to explain how each integration affects your scope.

Need our compliance documents?

We share our current PCI DSS Attestation of Compliance with merchants, partners and acquirers as part of due diligence. Ask our team and we will send it to you.